Analysis Towards Vmem File Of A Suspended Virtual Machine

Zheng Song,Bo Jin,Yongqing Sun
DOI: https://doi.org/10.1007/978-3-642-18134-4_15
2011-01-01
Abstract:With the popularity of virtual machines, forensic investigators are challenged with more complicated situations, among which discovering the evidences in virtualized environment is of significant importance. This paper mainly analyzes the file suffixed with .vmem in VMware Workstation, which stores all pseudo-physical memory into an image. The internal file structure of .vmem file is studied and disclosed. Key information about processes and threads of a suspended virtual machine is revealed. Further investigation into the Windows XP SP3 heap contents is conducted and a proof-of-concept tool is provided. Different methods to obtain forensic memory images are introduced, with both advantages and limits analyzed. We conclude with an outlook.
What problem does this paper attempt to address?